Page MenuHomePhabricator

RFSTag
ArchivedPublic

Mitglieder

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

A request for service is a systematic request for which a standard operating procedure should exist. This type of work is often converted to an Epic if it is long tailed, but not always.

Neueste Aktivität

Wed, Jul 31

sbassett added a comment to T367995: Security Preview for shared login domain.

Do you mean the shared login domain specifically or the SUL3 project in general? (I'll file another security preview request about T363699: Determine and implement SUL 3 login handshake mechanism in a day or two, once I have PoC code. I think these are the two particularly security-sensitive parts of the project, the rest of the work is less interesting.)

Wed, Jul 31, 5:29 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Mon, Jul 29

Krinkle updated the task description for T367995: Security Preview for shared login domain.
Mon, Jul 29, 6:44 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Wed, Jul 24

Tgr updated subscribers of T367995: Security Preview for shared login domain.

Do you mean the shared login domain specifically or the SUL3 project in general? (I'll file another security preview request about T363699: Determine and implement SUL 3 login handshake mechanism in a day or two, once I have PoC code. I think these are the two particularly security-sensitive parts of the project, the rest of the work is less interesting.)

Wed, Jul 24, 10:29 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
sbassett added a comment to T367995: Security Preview for shared login domain.

Hey @Tgr - I'd like to set up an initial threat-modeling/concept-review session (or two) for this work with you and any other relevant folks, this quarter. Are there any other technical folks that you're aware of who would likely be helpful during or interested in participating in such exercises? Thanks.

Wed, Jul 24, 4:20 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Tue, Jul 16

Tgr added a comment to T367995: Security Preview for shared login domain.

The configuration is now live in the beta cluster - the domain is not used for anything yet, but it works.
Example of an allowed request: https://sso.wikimedia.beta.wmflabs.org/en.wikipedia.beta.wmflabs.org/wiki/Special:UserLogin
Example of a disallowed request: https://sso.wikimedia.beta.wmflabs.org/en.wikipedia.beta.wmflabs.org/wiki/Main_Page

Tue, Jul 16, 7:35 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Tue, Jul 9

Tgr changed the visibility for T367995: Security Preview for shared login domain.
Tue, Jul 9, 8:44 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Tgr added a comment to T367995: Security Preview for shared login domain.

Does this need to be security protected?

Tue, Jul 9, 8:43 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Mon, Jul 8

Tgr updated subscribers of T367995: Security Preview for shared login domain.
Mon, Jul 8, 10:04 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jul 3 2024

Aklapper archived RFS.
Jul 3 2024, 6:57 PM
sbassett changed the status of T367995: Security Preview for shared login domain from Open to In Progress.
Jul 3 2024, 5:13 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
sbassett moved T367995: Security Preview for shared login domain from Upcoming Quarter Planning Queue to In Progress on the secscrum board.
Jul 3 2024, 5:12 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 28 2024

Tgr moved T367995: Security Preview for shared login domain from Backlog to Blocked / External on the SUL3 board.
Jun 28 2024, 1:10 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 27 2024

Jgreen updated the task description for T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 27 2024, 10:04 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen updated the task description for T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 27 2024, 10:03 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen renamed T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring. from Investigate starburst(trino) install, operation and maintenance, and security monitoring. to Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 27 2024, 10:02 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 26 2024

Jgreen added a comment to T367817: Investigate Dagster packaging, install, security monitoring..

Updated list:

Jun 26 2024, 7:00 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 24 2024

sbassett edited projects for T367995: Security Preview for shared login domain, added: SecTeam-Processed; removed Security-Team.
Jun 24 2024, 4:11 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
sbassett moved T368108: Investigate Superset packaging, install, security monitoring. from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 24 2024, 3:08 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 20 2024

Jgreen added a comment to T367817: Investigate Dagster packaging, install, security monitoring..

For Debian Bullseye, the following pip packages get installed to the Dagster venv:

Jun 20 2024, 8:23 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen renamed T367817: Investigate Dagster packaging, install, security monitoring. from Investigate dagster packaging, install, security monitoring. to Investigate Dagster packaging, install, security monitoring..
Jun 20 2024, 8:22 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T368108: Investigate Superset packaging, install, security monitoring..

For Debian Bullseye, the following packages get installed to the Superset venv:

Jun 20 2024, 8:20 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen created T368108: Investigate Superset packaging, install, security monitoring..
Jun 20 2024, 8:16 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett moved T367995: Security Preview for shared login domain from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 20 2024, 3:46 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Tgr added a comment to T367995: Security Preview for shared login domain.

Probably not? I used the link at https://www.mediawiki.org/wiki/Security/SOP/Security_Preview and that created it like that.

Jun 20 2024, 11:25 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Reedy added a comment to T367995: Security Preview for shared login domain.

Does this need to be security protected?

Jun 20 2024, 11:12 AM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 19 2024

Tgr added a parent task for T367995: Security Preview for shared login domain: T363695: Create a Wikimedia login domain that can be served by any wiki.
Jun 19 2024, 8:48 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS
Tgr created T367995: Security Preview for shared login domain.
Jun 19 2024, 8:47 PM · SecTeam-Processed, secscrum, SUL3, Security Preview, RFS

Jun 17 2024

sbassett moved T367817: Investigate Dagster packaging, install, security monitoring. from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 17 2024, 9:10 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett moved T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring. from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Jun 17 2024, 9:10 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen created T367818: Investigate Trino/Starburst install, operation and maintenance, and security monitoring..
Jun 17 2024, 8:58 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T367123: Investigate minio packaging, install, security monitoring..

There's a script in the internal frack "packages" repository that fetches the package and reports the portion of changelog associated with the latest package. The deb package is then added to the frack internal repository using "reprepro includedeb".

Jun 17 2024, 8:43 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T367817: Investigate Dagster packaging, install, security monitoring..

The basic install of dagster and its dependencies has been puppetized. Puppet also configures a pip-audit script to check for updates in the virtualenv and emails with success (clean audit) or an alert (patches are available). There's no project configuration in puppet yet, this part will be developed with BDC.

Jun 17 2024, 8:37 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen updated the task description for T367817: Investigate Dagster packaging, install, security monitoring..
Jun 17 2024, 8:35 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen created T367817: Investigate Dagster packaging, install, security monitoring..
Jun 17 2024, 8:35 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 12 2024

sbassett moved T367123: Investigate minio packaging, install, security monitoring. from Back Orders to Upcoming Quarter Planning Queue on the secscrum board.
Jun 12 2024, 4:12 PM · SecTeam-Processed, Privacy Engineering, Security Preview
sbassett moved T367123: Investigate minio packaging, install, security monitoring. from Incoming to Back Orders on the secscrum board.
Jun 12 2024, 4:07 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 11 2024

Jgreen added a comment to T367123: Investigate minio packaging, install, security monitoring..

More on vulnerability tracking. This isn't awesome but:

Jun 11 2024, 9:14 PM · SecTeam-Processed, Privacy Engineering, Security Preview
Jgreen added a comment to T367123: Investigate minio packaging, install, security monitoring..

https://github.com/minio/minio/security executive summary: watch the blog :-|

Jun 11 2024, 8:12 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Jun 10 2024

Jgreen created T367123: Investigate minio packaging, install, security monitoring..
Jun 10 2024, 9:27 PM · SecTeam-Processed, Privacy Engineering, Security Preview

Dec 13 2023

sbassett changed the visibility for T353306: [request] consultation for a whitepaper.
Dec 13 2023, 3:04 PM · SecTeam-Processed, Privacy Engineering, Research
leila moved T353306: [request] consultation for a whitepaper from Backlog to Support Needed on the Research board.
Dec 13 2023, 7:25 AM · SecTeam-Processed, Privacy Engineering, Research
leila added a project to T353306: [request] consultation for a whitepaper: Research.
Dec 13 2023, 7:25 AM · SecTeam-Processed, Privacy Engineering, Research
leila created T353306: [request] consultation for a whitepaper.
Dec 13 2023, 7:25 AM · SecTeam-Processed, Privacy Engineering, Research

Nov 6 2023

sbassett triaged T347576: Including donor's first name as a URL parameter. as High priority.
Nov 6 2023, 4:54 PM · Privacy Engineering, SecTeam-Processed
sbassett added a comment to T347576: Including donor's first name as a URL parameter..

JS was updated to sanitize the name being injected.

Nov 6 2023, 4:54 PM · Privacy Engineering, SecTeam-Processed
JFishback_WMF closed T347576: Including donor's first name as a URL parameter. as Resolved.

JS was updated to sanitize the name being injected.

Nov 6 2023, 4:15 PM · Privacy Engineering, SecTeam-Processed

Nov 3 2023

JFishback_WMF updated subscribers of T347576: Including donor's first name as a URL parameter..
Nov 3 2023, 7:51 PM · Privacy Engineering, SecTeam-Processed
acooper added a comment to T347576: Including donor's first name as a URL parameter..

We have concerns that the following code snippet from this feature contains a XSS that might be triggered by a malicious link opened by a user:

Nov 3 2023, 7:03 PM · Privacy Engineering, SecTeam-Processed
JFishback_WMF updated subscribers of T347576: Including donor's first name as a URL parameter..
Nov 3 2023, 6:45 PM · Privacy Engineering, SecTeam-Processed
JFishback_WMF added a comment to T347576: Including donor's first name as a URL parameter..

@sbassett Did AppSec review the JS to ensure that any parameters are scrubbed before injecting on the page?

Nov 3 2023, 6:29 PM · Privacy Engineering, SecTeam-Processed